Measuring and Allocating Systemic Risk

In this paper we develop a framework for measuring, allocating and managing systemic risk. SystRisk, our measure of total systemic risk, captures the a priori cost to society for providing tail-risk insurance to the financial system. Our allocation principle distributes the total systemic risk among individual institutions according to their size-shifted marginal contributions. To describe economic shocks and systemic feedback effects we propose a reduced form stochastic model that can be calibrated to historical data. We also discuss systemic risk limits, systemic risk charges and a cap and trade system for systemic risk. <br>


Introduction
The purpose of this paper is to develop a framework for measuring, allocating and managing systemic risk. Financial services play an important role in modern free market economies. Therefore, governments often do not have a choice but to provide support to failing financial institutions in order to protect the broader economy. We address this issue by studying the following two questions: (i) how to measure the total systemic risk generated by the financial sector and (ii) how to allocate the total systemic risk to individual financial institutions ? We view possible government support of financial institutions as an externality and measure total systemic risk by determining its a priori cost to society. To allocate the total systemic risk among individual institutions we propose to use their marginal contributions. To describe economic shocks, spillover, amplification and adverse feedback effects we develop a reduced form stochastic model that can be calibrated to historical data.
The most important features of our approach are: • It views financial institutions as parts of the financial system. For instance, a bank that behaves as part of a herd is allocated more systemic risk than a bank that acts independently of the rest of the financial sector.
• It relates the financial industry to the real economy. As a consequence, costs of externalities grow faster than proportionally if they become large compared to a country's GDP. Moreover, negative externalities that happen in states of the world where the overall economy is strong cost less than those that happen when the economy is weak.
• It satisfies the so called clone property. That is, if a financial institution is split into n equal parts, the total systemic risk does not change and the risk attributed to the institution also splits into n equal parts.
• It can detect risks that might not be fully reflected in market quotes of traded securities since it considers scenarios in which taxpayers provide support to financial institutions, resulting in distorted market prices.
• It can detect systemic risk in low volatility environments in which the risk of large economic shocks is low but the financial system is prone to negative feedback spirals in case a crisis erupts.
• It is based on a tolerance parameter that can be adjusted over time so as to implement countercyclical regulation.
During financial crises governments might have to support certain parts of the financial system to maintain a properly functioning economy. Whether this happens through loans, restructuring or nationalization, it amounts to costs that ultimately are borne by the taxpayers. SystRisk, our measure of total systemic risk, quantifies the a priori cost of this externality to society. It has the appealing feature that it grows faster than linearly as the exposures become large compared to the real economy. It also gives more weight to losses occurring in states of the world in which the overall economy is depressed. We distribute the total systemic risk among the components of the system based on their marginal contributions and provide a formula that expresses them as expectations with respect to a shadow pricing measure. Typically, they add up to more than the total systemic risk. We propose to reduce them proportionally to exogenous size parameters such as, for instance, the amount of corporate tax an institution payed in the previous year. This yields an allocation principle that attributes systemic risk to individual entities according to the role they play in the financial sector. If a financial firm is part of a herd or exposed to spillover effects, it is assigned more systemic risk than one that is more independent and better prepared to withstand a financial crisis.
Systemic risk can build up during economic booms but only materialize when a crisis erupts. If not taken into account by regulation, this can lead to the situation that a financial system is more vulnerable when observed volatility is low, a phenomenon coined "volatility paradox" in Brunnermeier and Sannikov (2014). The reason for this is that in a low volatility environment financial institutions might be induced to lever up and increase the liquidity mismatch of their balance sheets, that is, they are holding assets of low market liquidity which in a crisis can only be sold at a high discount, and a large part of their funding is short-term and hence, has to be rolled over frequently. 1 We account for this by developing a simple two-stage reduced form model that can be calibrated to historical data. In a first step, individual firms receive shocks to their balance sheets. They can be the consequence of changes of macroeconomic variables or can originate within individual firms. In a second step, feedback effects play out between the institutions. While past crises have been triggered differently, systemic feedback mechanisms have exhibited similar patterns. 2 Our model differentiates between direct and indirect feedback effects. Direct effects happen when there exist contractual connections between companies. A defaulting firm directly impacts the balance sheets of its counterparties possibly triggering further defaults. Indirect feedback effects are caused by fire sales of illiquid assets and dry ups of funding liquidity. They are more pronounced if the liquidity mismatch of financial firms is high since this makes them more vulnerable to sudden declines in market liquidity and increases in short-term interest rates. By explicitly including systemic feedback effects, our approach addresses the volatility paradox. SystRisk is also less procyclical than standard risk measures, which typically do not pick up systemic risk in boom times and skyrocket when a crisis erupts, forcing institutions to delever, which in turn increases the risk measure further and worsens the crisis. In addition, we allow for a tolerance parameter that describes how much systemic risk a society is willing to bear. It can be adjusted so that more risk is tolerated during economic downturns to provide conditions for the economy to stabilize and return to a path of growth.
Any systemic risk measure naturally raises the question how it can be used to manage and regulate systemic risk. SystRisk and our allocation principle show where systemic risk is building up and provide guidance in which direction financial regulation is most effective in reducing it. However, financial institutions have their own objectives and will react to new rules. To find a socially optimal level of regulation, one can attempt to model the behavioral response of all market participants and develop a full equilibrium model. But doing this realistically is beyond the scope of this paper. The financial sector consists of many heterogeneous institutions. For example, banks will react differently than insurance companies, which in turn will have a different response from pension funds, sovereign wealth funds and hedge funds. In addition, many firms will try to circumvent regulatory measures. We adopt a more cautious tatonnement approach and view financial regulation as an ongoing process rather than the establishment of ultimate rules. In other words, regulation is introduced knowing that it might have to be reoptimized based on observed responses by financial institutions and updates of systemic risk measures. In this procedure the tolerance parameter has a second important role to play. It can be adjusted iteratively to find an optimal tradeoff between financial stability and enough leeway for financial firms to be able to provide the services a modern society depends on.
We discuss three different implementations of financial regulation: (i) setting individual risk limits, (ii) imposing risk charges, and (iii) implementing a cap and trade system. Setting individual risk limits is closest to current financial regulation in most developed countries. But in contrast to classical banking regulation, which views each firm as a separate entity, our method leads to risk limits for individual institutions that depend on the positions of other institutions and how the financial sector is related to the rest of the economy. Alternatively, in the spirit of Pigouvian taxes, one can impose systemic risk charges depending on the positions the institutions are taking. This can be viewed as an extension of deposit insurance premiums. But again, the risk charges proposed here depend on a financial institution's contribution to systemic risk. Systemic risk limits can be complemented with a cap and trade scheme. For instance, an auction for systemic risk permits can be held, which then can be traded during a certain period of time. This has two advantages. First, it might allow the financial sector to mitigate systemic risk more efficiently, and second, it produces a market price for systemic risk.
Over The rest of the paper is organized as follows: In Section 2 we define SystRisk, our measure of systemic risk of the financial sector. Section 3 introduces our systemic risk allocation principle. In Section 4 we propose a stochastic model for initial random shocks to the financial system and ensuing amplification mechanisms playing out within it. Section 5 discusses three different ways for the regulator to manage systemic risk. Setting individual risk limits, imposing systemic risk charges and implementing a cap and trade scheme for systemic risk. All proofs are collected in the appendix.

Measuring total systemic risk
In this section we introduce our approach to measuring systemic risk in a general setting in which financial institutions cause externalities on society. A more specific model of financial losses and resulting externalities are discussed in Section 4 below.
We work with a finite set Ω of different states of the world. Then the space L of all mappings X : Ω → R can be identified with R d , where d is the number of elements in Ω. We write • P := the set of all probability measures on Ω • P f := the set of all probability measures on Ω with full support.

The regulator
We assume there is a regulator overseeing a country's financial sector. It represents taxpayers, who in the event of a financial crisis, might have to prop up financial firms to prevent a collapse of the real economy. We fix a time period (e.g. a year or a quarter of a year) and model the country's real GDP generated over that period with a random variable Y ∈ L. We think of Y as the output of the real economy when it receives the financial services it needs to function properly. If essential parts of the financial system break down, the rest of the economy suffers severe consequences. To prevent this, the government is assumed to step in and provide the support necessary to keep the most important financial functions intact. This represents a negative externality caused by the financial sector. On the other hand, financial institutions can also have positive externalities if they perform better than expected. We assume that the aggregate utility society is deriving from Y is given by U (Y ) for a preference functional U : consists of all elements X ∈ L for which U (X) is real-valued. The interior of dom U is given by The particular form of our systemic risk measure and allocation rule will depend on how the preference functional U is specified. But the approach works with any U satisfying the following two conditions. We assume them to hold throughout the paper.
We denote the gradient of U at X by ∇U (X). A natural choice of U for our purposes is a CRRA expected utility for a relative risk aversions γ > 1 since it is the preference functional of a representative agent resulting from aggregating individual CRRA expected utility maximizers. If the probability measure P has full support and (1) where · denotes the standard scalar product on R d . It is clear that (1) also satisfies condition (S) on L ++ . More generally, (D) and (S) are satisfied for any expected utility U (X) = E P [u(X)] as long as P has full support and u : R → R ∪ {−∞} is a function with non-empty effective domain dom u = {x ∈ R : u(x) ∈ R} that is strictly increasing and differentiable on the interior of dom u. For X ∈ int dom U , one has Going beyond expected utility, model uncertainty can be incorporated by introducing a nonempty closed subset Q ⊆ P together with a lower semicontinuous mapping c : Q → R and defining for a function u : R → R ∪ {−∞}. Preferences of this type, called variational preferences, were axiomatized by Maccheroni et al. (2006). If u is strictly increasing on int dom u and Q is contained in P f , U satisfies (S). Moreover, if dom u is non-empty, u is differentiable on int dom u and c is chosen appropriately, U also has the differentiability property (D). For example, it is well-known (see, e.g., Föllmer and Schied, 2004) that for Q = P, γ > 0, P ∈ P f and c(Q) = 1 γ E dQ dP log dQ dP , (2) becomes which satisfies (D) and (S) if u is strictly increasing and differentiable on int dom u.

The financial system
We suppose that the financial system consists of I ∈ N institutions, each of which causes an externality of the form • V i ∈ L is the net worth of institution i at the end of the measuring period, calculated e.g., as market value of assets minus book value of liabilities. V i is assumed to already include non-linearities generated by negative feedback effects occurring during a crisis. A reduced form stochastic model for • α i ≥ 0 is a constant, and the term α i V − i describes a potential cost to society if institution i's net worth falls below zero. We assume α i to be a number between 0 and 1. To avoid moral hazard, it is important that there be no bailout guarantee. But we assume that in case of a crisis, the government decides on a case by case basis which institutions have to be supported to prevent negative effects on the real economy. Companies could receive a mix of bailout payments and government loans at preferred conditions, or they could be nationalized. In all these cases some of the losses have to be borne by the taxpayer. We allow α i to depend on the type of institution i since the cost caused by a bankruptcy depends on the structure of a financial company. For instance, a financial institution with several different business lines is more difficult to save or liquidate than one which concentrates only on a few activities. Furthermore, a typical bank relies heavily on short-term debt financing. So to protect the economy from an impending collapse, a relatively high fraction of its losses will have to be covered. Other components of the financial system, such as insurance companies or pension plans have more long-term liabilities and can continue operating even if their net worth falls below zero. As a consequence it might be possible to help them through a crisis with a minimal amount of funding.
• β i , v i ≥ 0 are constants, and β i (V i − v i ) + models a possible positive externality. For instance, if institution i's net worth exceeds the level v i , the government may benefit from additional tax revenues of the form If the aggregate externality E := i∈I E i is absorbed by society, the real GDP changes from Y to Y + E. Our approach only needs the pair (Y, E) as input to determine the total systemic risk. To solve the systemic risk allocation problem we will have to specify the members of the financial system further. This will be done in Section 3 below.

Total systemic risk
We assume the regulator determines a tolerance level e ∈ R satisfying U (Y + e) > −∞ and deems an externality E acceptable if U (Y + E) ≥ U (Y + e). For a given externality E ∈ L, we are asking how much money the regulator would have to receive to be compensated for absorbing E. This leads to the following definition of systemic risk.
Note that ρ(E) is the cost of the externality E measured in currency units at the end of the measuring period. If used to determine systemic risk charges to be collected beforehand, it has to be discounted at the risk-free rate. For monitoring purposes, one can fix e = 0. But if SystRisk is used for regulation, the regulator can decide to set e < 0. Then negative externalities are tolerated as long as their impact is not too severe. Moreover, by adjusting the tolerance level e to the economic situation, the regulator can fine tune the stringency of financial regulation and implement countercyclical policies. For instance, in a recession financial regulation can be relaxed to permit the financial sector to operate with fewer constraints.
Under our assumptions on U , ρ has the following properties: In particular, ρ is a monetary risk measure on L in the sense of Föllmer and Schied (2004). But since it is of the special form (3), it has additional properties. The next result shows that ρ is differentiable and strictly decreasing at all E ∈ L satisfying the condition This will be important for the risk allocation method proposed in Section 3. Note that if E satisfies (I), the gradient ∇U (Y + E + ρ(E)) exists, and since U has the strict monotonicity property (S), all its components are strictly positive. So defines a probability measure with full support.
In particular, all components of ∇ρ(E) are strictly negative, and ρ is differentiable at every E ∈ L satisfying (I) with gradient ∇ρ(E) = −Q E , where the shadow pricing measure Q E is given by .
Note also that (7) is concave on L and strictly concave on int dom U = L ++ ; that is, for all λ ∈ (0, 1), one has and the inequality is strict if X, X ∈ L ++ such that X = X . This implies that ρ is convex. More precisely, the following holds: concave, then ρ is convex and can be represented as Moreover, for all E ∈ L satisfying (I), Q E is the unique maximizer in (8).
If furthermore, U is strictly concave on int dom U , then for all 0 < λ < 1 and E, E ∈ L satisfying (I) such that E − E is non-deterministic.
(8) expresses ρ as a maximum of shifted expectations with respect to different probability measures. This is called robust representation in the risk measure literature; see e.g., Föllmer and Schied (2004) or Li (2008, 2009). Every real-valued convex function on a finite-dimensional vector space has a representation as a maximum of affine functions. That the maximum in (8) can be taken over the set of probability measures P is due to the fact that ρ has the monotonicity property (M) and the translation property (T). That Q E is the unique maximizer in (8) follows from the differentiability assumption (D). Details are given in the appendix.
As a consequence of Proposition 2.4, one obtains that in case U is concave and strictly concave on int dom U , the systemic risk measure ρ scales superlinearly: Corollary 2.5 Assume U is concave on L and strictly concave on int dom U . Let E ∈ L be a non-deterministic externality satisfying (I). Then ρ(λE) > λ(ρ(E) − e) + e for all λ > 1.
Relation (9) means that if financial institutions decide to change their positions such that their aggregate externality on the rest of society increases from E to λE for a constant λ > 1, then SystRisk increases by more than λ. This stems from the fact that externalities are compared to the size of the real GDP Y and a strictly concave preference functional U corresponds to a risk averse representative taxpayer.

Systemic risk allocation
It is important to know how much each component of the financial system contributes to overall systemic risk. We propose an allocation rule based on externalities. They can result from macroeconomic and idiosyncratic shocks as well as feedback effects between financial institutions (a detailed model is given in Section 4 below). In particular, the externalities of one firm can be affected by the behavior of others. But it is each institution's own responsibility to manage its exposure to spillover risk.
A risk allocation is simply a vector k = (k 1 , . . . , k I ) ∈ R I whose components specify how much of the total risk is allocated to the i-th institution. If the allocation is used to implement capital requirements or systemic risk charges, it should satisfy (FA) Full allocation: But for monitoring purposes alone, (FA) is not necessary. For instance, the with-without allocation (see e.g. Merton andPerold, 1993, or Matten, 1996) does not satisfy (FA). But on the other hand, it has the following two properties: (RA) Riskless allocation: (CR) Causal responsibility: If the i-th externality changes from E i to E i = E i + ∆E i for some ∆E i ∈ L and E j = E j for j = i, then the adjusted allocation k satisfies k i − k i = ρ(E + ∆E i ) − ρ(E).
(RA) means that if it is clear in advance that firm i will cause an externality costing m units of currency, then its systemic risk allocation should be m. If an allocation principle satisfies (CR) and one of the firms decides to change its exposure, it has to bear the full cost of the resulting change in total systemic risk. Note that under the allocation rule (10), a change in one firm's externality also affects the others. Their allocations change from But if ∆E i is small compared to E, then k j is close to k j . W W i can be approximated with the marginal contributions If E satisfies condition (I), it follows from Theorem 2.3 that the marginal contributions exist. They still satisfy (RA), and (CR) holds approximately. Moreover, they have the following property: (AD) Additivity: If firms i and j are merged in such a way that the externality of the combined unit becomes E i+j = E i + E j and the externalities of the other firms stay the same, then the new allocation k satisfies k i+j = k i + k j as well as k l = k l for l = i, j.
The marginal contributions (11) still do not satisfy (FA). But the following proposition shows that if U is concave and e ≤ 0, they sum up to at least the total systemic risk ρ(E).
where µ ∈ R is chosen so that the full allocation principle (FA) holds.
The parameters s i are meant to reflect the institutions' sizes and should not be easy to manipulate with the intent to avoid regulation. For instance, they can be chosen as the amount of corporate taxes paid last year. Then, if the assumptions of Proposition 3.1 hold, (12) reduces the marginal contribution of each firm by an amount that is proportional to the taxes it payed in the previous year. The size-shifted marginal contributions satisfy (FA) by construction. Technically, they violate (RA). But if a financial institution is liquidated immediately in case it has a deterministic negative externality and exempted from regulation if the externality is deterministic positive, the remaining externalities are non-deterministic, and (RA) holds trivially. Moreover, the size-shifted marginal contributions (12) satisfy (CR) approximately, and if the size parameters s i add up in mergers, they inherit the additivity property (AD) from the marginal contributions (11). That is, the allocation rule (12) is additive in the externalities. However, while it is natural to assume that the size parameters of merging companies add up, their externalities can behave in a number of different ways. The precise behavior of externalities under mergers depends on the relation between the future net worths V i . This issue is discussed in more detail in Subsection 4.4 below. Note that the 2010 Dodd-Frank Act in the United States also acknowledges that some financial institutions are more systemically important than others. For this reason the Financial Stability Oversight Council was established, one of whose main tasks is to designate certain financial institutions as systemically important (SIFIs). The current designation procedure looks at a variety of variables, including size, leverage and stress-test performance. Our systemic risk allocation goes beyond a zero-one designation, as it also captures the degree to which an institution contributes to overall systemic risk.

Modeling losses in the financial sector
In this section we propose a reduced form model for losses in the financial sector and resulting externalities. The suggested model has the advantage that its coefficients can be estimated from historical data. But our approach also works with a different underlying model, like for instance, a simulation model such as the RAMSI model of Burrows et al. (2012), the interaction model of of Puhr and Schmitz (2014), the Macro-Financial Risk Assessment Framework of Fique (2017), or the agent based model of Bookstaber et al. (2018).
We assume that losses in the financial system are the result of initial random shocks and negative feedback effects in the system.

Initial losses
Initial shocks can be caused by macroeconomic factors or firm specific events. We suppose that at the beginning of the measuring period every institution of the financial system starts with a deterministic net worth x i ∈ R. Then all of them receive a random shock of the form z i (F, W i ), where F = (F 1 , . . . , F n ) ∈ L n is a vector of macroeconomic variables, W i ∈ L is a firm-specific shock 3 and z i : R n+1 → R a deterministic function. After the initial shocks the institutions' net worths are

Feedback mechanisms
In a second step, spillover effects between financial institutions take place, potentially amplifying the crisis. We divide them into direct and indirect spillover effects.
• Direct spillovers are caused by contractual connections between firms.
• Indirect spillover effects that played an important role in the subprime mortgage crisis starting in 2007 were asset fire sales and the dry up of funding liquidity. Asset fire sales occur when firms sell illiquid assets. This creates downward pressure on their prices and affects other institutions that are holding them. Funding liquidity dries up when, due to distress in some parts of the financial sector, lenders become more risk averse and suddenly demand higher interest. This is especially problematic for firms with a lot of short term debt since they have to refinance more frequently.
To capture vulnerabilities to direct spillover effects, we introduce an I × I-matrix c = (c ij ) i =j of interconnectedness (it does not need diagonal elements, or they can be set equal to zero). Component c ij of the interconnectedness matrix c gives a measure of future cash flows to be paid by institution i to institution j. If the former is in distress, it might not be able to honor its commitments, creating a problem for the latter. Indirect spillover effects depend on liquidity mismatches. Denote by l = (l 1 , . . . , l I ) the vector of liquidity mismatch indexes of the firms i ∈ I. They measure the firms' debt structure compared to the market liquidity of their assets. If the majority of an institution's debt is long term and all its assets can easily be sold in a crisis, it will not be affected by indirect spillover effects. Consequently, its liquidity mismatch index is low.
On the other hand, if it has a lot of short term debt and many illiquid assets, it is more prone to indirect spillovers and has a high liquidity mismatch index; see .
We describe negative feedback effects by assuming that after the arrival of the initial shocks, amplification effects move institution i's net worth from X i to where a i : R n+I+I 2 → R is a deterministic function (F has n components, X and l each have I components, and the matrix c has I 2 − I non-trivial entries).
The global financial crisis was triggered by the collapse of the US subprime mortgage market in 2017. This market was small relative to the overall US mortgage market and tiny compared to the size of the global financial markets. The reason that problems in the US subprime mortgage market could trigger a global crisis of a scale second only to the great depression of the 1930s, was the vulnerability of the financial system to spillover and amplification effects. These effects were caused by liquidity mismatch and leverage. A significant fraction of the liquidity mismatch was disguised in the shadow banking system; see e.g., Pozsar et al. (2012) and Bengtsson (2016). Our reduced form model is designed to capture direct contagion, amplification mechanisms as well as adverse feedback effects in the shadow banking system.

The regulator
We assume that the GDP of the real economy is of the form Y = y(F ), where the components of F = (F 1 , . . . , F n ) are the macroeconomic variables introduced in Subsection 4.1 and y : R n → R is a deterministic function. Suppose that E satisfies condition (I). Then we obtain from Theorem 2.3 that the gradient of ρ at E acts on a random variable E ∈ L like For instance, if U is a CRRA expected utility E P [u(x)] for a probability measure P ∈ P f and a function u of the form then U is strictly concave on int dom U , and .
So it follows from Corollary 2.5 that for e ≤ 0, one has This means that if the financial sector decides to behave in way such that the aggregate externality multiplies by a factor λ > 1, then total systemic risk increases more than proportionally. The sizeshifted marginal contributions of Definition 3.2 take the form where µ ∈ R + has to be chosen so that the full allocation principle (FA) holds.

Mergers and spinoffs
We now discuss how systemic risk is affected by mergers and spinoffs. We consider m firms i 1 , . . . , i m in I and compare the case where they are separate entities to the one where they are merged into one big company. We assume that a merger does not affect the initial shocks z i (F, W i ) and the size parameters s i add up. Then, without restructuring, the net worth of the combined unit after the occurrence of initial shocks isX = m j=1 X i j and its size parameterŝ = m j=1 s i j . But after that there are two layers of non-linearities.
1. Amplification mechanisms are non-linear. SoV is not necessarily equal to the sum m j=1 V i j .
2. Externalities are non-linear in final net worths. So even ifV equals m We recall that firm i's externality is for parameters α i , β i , v i ∈ R + , whereas the merged firm causes an externality of the form Depending on the circumstances, mergers and spinoffs can have varying effects on total systemic risk. In the following we discuss three different scenarios:

Clone property
As a benchmark, we first consider the case where the firms i 1 , . . . , i m are clones in the sense that they start with the same initial net worths x i , are of the same size s i , have identical exposures and react in the same way to shocks. In particular, they receive the same initial shocks and respond identically. This leads to equal final net worths V i . Moreover, since they all experience identical gains and losses in the same scenarios, negative feedback effects should not depend on whether the firms operate independently or as one combined company. So, in this special case, final net worths and externalities both add up; that is,V = m j=1 V i j = mV i 1 andÊ = m j=1 E i j = mE i 1 . In particular, the total systemic risk ρ(E) does not change, and since the size-shifted marginal contributions (12) have the additivity property (AD), SystRisk and our allocation principle satisfy the following Clone property: Under a merger of the clones i 1 , . . . , i m , the total systemic risk ρ(E) as well as the size-shifted marginal contributions of the firms different from i 1 , . . . , i m stay the same, while the size-shifted marginal contribution of the new firm is mSM C i 1 .

Reducing systemic risk through spinoffs
From the perspective of systemic risk, the goal of spinoffs should be to separate large financial institutions into different business units so as to prevent the spread of problems and facilitate liquidations in case of insolvency. This will not reduce losses in all possible scenarios. For instance, in case V i 1 < 0 and V i 2 , . . . , V im ≥ 0, the first of the small firms goes bankrupt if they are separate entities while it could have been saved by the others, had they been part of the same company. That is, large institutions are more diversified and can compensate small losses in one line of business with gains from others. However, if done properly, spinoffs have two benefits: (i) They introduce fire walls and reduce negative feedback effect resulting in less severe aggregate losses during crises. So with non-linear amplification effects, large values of m j=1 V − i j are less likely than large values ofV − . (ii) Small firms with few business lines are easier to support or wind down in times of turmoil than multinational financial conglomerates. This must be reflected by setting the cost coefficientα for conglomerates higher than those for less complex institutions α i 1 , ..., α i k (by choosing, for instance, α i as an increasing function of the number of business lines of firm i). All in all, if a complex financial institution is split into simpler parts, the likelihood that m j=1 E j i takes large negative values decreases compared toÊ. This reduces total systemic risk as well as the contribution of the firms i 1 , . . . , i m to the whole.

Cases where spinoffs increase systemic risk
If a large financial institution is divided into smaller parts in a way that does not reduce negative amplification effects or complexity, total systemic risk can go up. If for instance,V = m j=1 V i j , α = α i 1 = · · · = α im = α,β = β i 1 = · · · = β im = β andv = v i 1 = · · · = v im = 0 for numbers α ≥ β ≥ 0, one hasÊ = ϕ(V ) and E i j = ϕ(V i j ) for all j = 1, . . . , m, for the super-additive function ϕ(x) = −αx − + βx + , and it follows thatÊ ≥ m j=1 E i j . That is, spinoffs have negative effects on externalities and increase total systemic risk. For example, if α > 0 and β = 0, only negative externalities are taken into account. So if the combined firm does not cause more negative feedback effects and is not more complex than the sum of the small ones, it is safer because it can use profits of one unit to absorb losses in another one.

Managing systemic risk: a discussion
There are different ways of managing systemic risk. Generally, the regulator regards the system as safe if ρ(E) ≤ 0. But if ρ(E) > 0, it poses an unacceptable risk that has to be mitigated. −∇ρ(E) points in the direction in which total systemic risk is reduced most effectively.
Financial institutions have their own aims and will respond to new regulation. But the financial system is heterogenous. A bank functions differently from an insurance company, pension plan, sovereign wealth fund or hedge fund. We do not model their behavior. This has the advantage that our approach does not depend on behavioral assumptions. But if new regulation is implemented, responses in the financial sector and their ramifications for the real economy have to be monitored.
The stricter the regulation, the tighter the constraints under which the financial sector has to operate. Our systemic risk measure and allocation principle show where the risk is coming from. By adjusting the tolerance parameter, the regulator can decide how much overall systemic risk to accept depending on current economic conditions.

Systemic risk limits
One way to manage systemic risk is to force each bank's systemic risk contribution towards zero. The regulator can guarantee ρ(E) ≤ 0 by requiring that all size-shifted marginal contributions satisfy SM C i ≤ 0, i = 1, . . . , I. If SM C i > 0 for some i, then firm i most efficiently changes its externality in the direction −∇ρ(E). Alternatively, one can determine the systemic capital surcharge for member i as the minimal amount of additional capital that makes SM C i fall to zero. This amounts to setting systemic risk limits and is close to current regulation in most modern economies. But standard financial regulation views financial firms as separate entities and ignores their systemic interactions.

Systemic risk charges
Instead of setting risk limits, the regulator can let financial firms act freely and charge them a premium for their contribution to systemic risk. If collected at the beginning of the measuring period, they have to be in the amount where r is the risk-free interest rate, so that total systemic risk is compensated. Compared to risk limits, systemic risk charges allow for the pooling of capital buffers. In case of a crisis they can be used to support failing components of the system. Moreover, if the abatement costs are only known to the financial institutions but not the regulator, imposing systemic risk charges has the advantage that firms can decide themselves how much risk is optimal for them to take on. Firms with low abatement costs will reduce their risk exposures to lower their charge. Others find it optimal to keep their positions and pay a higher premium. Systemic risk charges act like Pigouvian taxes. In contrast to systemic risk limits, they do not allow control of the aggregate risk in the financial system, but they require financial firms to pay compensation for it. To decide if it is preferable to regulate with systemic risk limits, charges or a mixture of the two is related to the classical question whether it is better to control an economic system through quantities or prices; see Weitzman (1974).

Cap and trade
Similarly to cap and trade schemes for the emission of pollutants, the regulator can distribute (for free or through an auction) a number P ∈ R + of systemic risk permits and require that each member of the system holds them in an amount P i such that SM C i − P i ≤ 0. A possible implementation is as follows. At the beginning of each measuring period (e.g. quarterly) permits are auctioned. Then they can be traded for a few days. A cap and trade system allows the regulator to control the overall level of systemic risk but lets the market decide how systemic risk is reduced most efficently. Those financial institutions with the lowest abatement costs can reduce their contributions and sell off extra permits to others for which a reduction of systemic risk is more expensive. In addition, a cap and trade system can provide valuable information. If permits trade at prices that correctly reflect the underlying fundamentals, they reveal the system's marginal abatement costs, which is useful information for the implementation of socially optimal regulation 4 .

Conclusions
This paper proposes a practical way of measuring and allocating systemic risk. It views the possibility that financial institutions might have to be supported in a crisis to protect the economy from negative consequences as an externality on society. SystRisk, our measure of total systemic risk, quantifies the a priori cost of this externality. It relates the financial industry to the real economy. Therefore, costs of externalities grow faster than linearly if they become large compared to the output of the real economy. Our approach is based on reduced form model that is designed to capture direct spillovers caused by defaults on claims between financial institutions as well as indirect feedback effects such as informational contagion, fire sales and liquidity spirals. Since we take into account that the financial sector might receive government support, SystRisk can detect risks that might not be fully reflected in market prices of traded instruments such as equity shares, bonds, options or credit default swaps. It also addresses the volatility paradox, which refers to the phenomenon that financial systems tend to be more vulnerable to systemic feedback effects if volatility is low. This is related to the procyclicality problem. Standard risk measures typically do not pick up systemic risk in economic booms but spike up sharply when a crisis erupts. If this is directly translated into tighter regulation, financial institutions are forced to decrease their leverage at the beginning of economic downturns, which exacerbates the problem. By incorporating leverage and liquidity mismatch, which make a financial system vulnerable to systemic feedback effects, our approach is able to identify systemic risk in low volatility environments. Moreover, it includes a tolerance parameter that can be adjusted over time to implement countercyclical regulation.
Our systemic risk allocation principle distributes total systemic risk among individual firms according to their size-shifted marginal contributions. This ensures that financial institutions are allocated systemic risk according to the role they play in the financial system. A financial firm that is part of a herd or exposed to spillover effects is assigned more systemic risk than one that is more independent and better prepared to withstand a financial crisis. Moreover, our method satisfies the so called clone property, that is, if a financial institution is split into n equal clones, the total systemic risk does not change, and the institution's risk contribution splits into n equal parts.
The paper outlines three different ways how our method of measuring and allocating systemic risk can be translated into financial regulation: setting systemic risk limits, imposing systemic risk charges, and a cap and trade system for systemic risk. Implementation of financial regulation that is fully optimal for the whole society would require an equilibrium model that can predict the behavioral response of financial institutions to regulatory requirements and the consequences for the real economy. This paper takes a reduced form approach in that it focuses on quantifying the cost of financial crises to society. Our method detects where systemic risk is coming from. Generally, stricter regulation means that the financial sector is under tighter constraints and therefore, can offer fewer services. By adjusting the tolerance parameter, the regulator can find the right level of stringency for an optimal balance between financial stability and enough flexibility for the financial sector to operate efficiently. This has to be achieved in an iterative process in which the regulator fine tunes the tolerance parameter and monitors the response from the financial sector and the effects on the rest of the economy.

A Proofs
Proof of Lemma 2.2 It is easy to check that if U satisfies (S) and U (Y + e) > −∞, ρ is a function from L to R with the properties (N), (M) and (T). So for E, E ∈ L, one has and by symmetry, which shows that ρ satisfies (L).
By Theorem 2.3, ρ is differentiable at every E ∈ L satisfying (I) with gradient ∇ρ(E) = −Q E . Since ρ is convex, one has ρ(E ) − ρ(E) ≥ E Q E [E] − E Q E [E ] for all E ∈ L. It follows that Q E is a maximizer in the representation (8), and it must be the unique maximizer because otherwise, ρ would not be differentiable at E.
If U is strictly concave on int dom U , choose E, E satisfying (I) such that E − E is nondeterministic. Then Y + E + ρ(E) and Y + E + ρ(E ) are both in int dom U , and one has U (Y + E + ρ(E)) = U (Y + E + ρ(E )) = U (Y + e).